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DETAILED ACTION 



Status of Claims 



1. 



This action is in reply to the amendment received on 23 February 2005. 



2. 



Claims 1, 2, 17, 29, 30, 31, 36, and 39 have been amended. 



3. 



Claims 1-50 have been examined. 



RESPONSE TO ARGUMENTS 



4. Applicant's arguments received on 23 February 2005 have been fully considered but they are not 
persuasive. Referring to the previous Office action, Examiner has cited relevant portions of the 
references as a means to illustrate the systems as taught by the prior art. As a means of 
providing further clarification as to what is taught by the references used in the first Office action, 
Examiner has expanded the teachings for comprehensibility while maintaining the same grounds 
of rejection of the claims, except as noted above in the section labeled "Status of Claims." This 
information is intended to assist in illuminating the teachings of the references while providing 
evidence that establishes further support for the rejections of the claims. 

With regard to the limitations of claims 1, 2, 17, 29, 30, 31, 36, and 39, Applicant argues 
that none of the cited references teach or otherwise suggest, alone or in combination, a 
repository of personal information. The Examiner asserts that Pare uses biometrics to control 
access to a user's bank account, and that Bianco uses biometrics to control access to enterprise 
resources and to specifically limit modification of the users personal information to the user. In 
addition, Bianco teaches a re-enrollment step that causes a modification of the physiological 
information of a users data set, clearly disclosing that an enrollment or registration step was 
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conducted prior to any re-enrollment step. In addition, the newly-cited art of Kanevsky discloses 
a repository of personal information including biometric samples. 

It is the continued opinion and position of this Examiner that the combination of Pare and 
Bianco discloses modification of personal information by utilizing physiologically-controlled 
access to a user's personal information. In support of this position, the Examiner uses Berson to 
teach a user modifying his own personal data while using biometric security protocols, and now 
includes the teachings of Kanevsky, also in support of the previous rejections. It appears as if the 
Applicant is attacking the prior art reference piecewise instead of in combination as intended by 
the Examiner and shown in the rejections below under 35 U.S.C. 103(a). As shown below, the 
combination of Pare, Bianco, Berson and Kanevsky discloses a system wherein personal 
information may be modified by a particular user using physiological identifiers to authenticate the 
user. 

With regard to claims 41 and 42, the common knowledge declared to be well-known in 
the art is hereby taken to be admitted prior art because the Applicant either failed to traverse the 
Examiner's assertion of Official Notice or failed to traverse the Examiner's assertion of Official 
Notice adequately. To adequately traverse the examiner's assertion of Official Notice, the 
Applicant must specifically point out the supposed errors in the Examiner's action, which would 
include stating why the noticed fact is not considered to be common knowledge or well-known in 
the art. A general allegation that the claims define a patentable invention without any reference 
to the Examiner's assertion of Official Notice would be inadequate. Support for the Applicant's 
assertion of should be included. 

Claim Rejections - 35 USC § 103 

5. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all obviousness 
rejections set forth in this Office action: 
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(a) A patent may not be obtained though the invention is not identically disclosed or 
described as set forth in section 102 of this title, if the differences between the subject matter 
sought to be patented and the prior art are such that the subject matter as a whole would 
have been obvious at the time the invention was made to a person having ordinary skill in the 
art to which said subject matter pertains. Patentability shall not be negatived by the manner 
in which the invention was made. 

6. Claims 1-42 are rejected under 35 U.S.C. 103(a) as being unpatentable over Pare Jr. et al. (U.S. 
Patent No. 6,154,879), in view of Bianco et al. (U.S. Patent No. 6,256,737), in view of Berson (US 
6,532,459 B1) t and further in view of Kanevsky (US 6,092,192 A). 

Examiner's note: Examiner has pointed out particular references contained in the prior art of 
record in the body of this action for the convenience of the Applicant. Although the specified 
citations are representative of the teachings in the art and are applied to the specific limitations 
within the individual claim, other passages and figures may apply. Applicant, in preparing the 
response, should consider fully the entire reference as potentially teaching all or part of the 
claimed invention, as well as the context of the passage as taught by the prior art or disclosed by 
the Examiner. 

Claims 1, 17, 29, 30, 31, and 36: 

Pare Jr. et al. shows, in figures 1-16 and related text, a method of administering 
registration of a personal information in a data base in a manner tending to assure integrity of 
data therein, the method comprising: obtaining, from each user with respect to whom data is to be 
placed in the data base, personal information of such user, the content of such personal 
information initially established by such user in an enrollment phase (column 13, lines 14-17); 
also obtaining in the enrollment phase a first set of physiological identifiers associated with such 
user (column 3, lines 43-46; column 13, lines 10-12); storing, in digital storage medium, a data set 
pertinent to such user, the data set including such user's personal information and a 
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representation of the physiological identifiers associated with such user (Fig 2); permitting a 
subject to modify information in the stored data set pertinent to such user (column 5, lines 11-13) 

Pare Jr. et al. fails to explicitly show the user information can be modified only if (i) the 
subject provides a new set of physiological identifiers and (ii) it is determined, by recourse to the 
stored data set, that there is a sufficient match between at least one member in the new set and a 
corresponding member of the first set, so that the subject is authenticated as such user. Bianco 
et al. shows, in figures 1-34 and related text, in an analogous art related to the utilization of 
biometric measurements for the authentication of users, permitting a subject to modify information 
in the stored data set pertinent to such user only if the subject provides a new set of physiological 
identifiers and it is determined, by recourse to the stored data set, that there is a sufficient match 
between at least one member in the new set and a corresponding member of the first set, so that 
the subject is authenticated as such user (column 29, lines 5-10). Bianco et al. states that the 
biometric system (Fig. 1) including the re-enrollment step can be usefully incorporated into 
banking and financial transaction systems (e.g. ATM machines) (Bianco, column 58, lines 5-14) 
therefore, it would have been obvious, at the time of the invention, to incorporate the re- 
enrollment step of Bianco into the biometric ATM access system of Pare. 

The combination of Pare/Bianco does not specifically disclose that the integrity of a 
registration system is maintained by permitting modification of a particular user's personal 
information only by that user, using physiological identifiers to authenticate the user. Berson, 
however, in column 2, lines 28-67, discloses a user modifying his own personal data, and in 
column 5, lines 12-33, disclose biometric security protocols. It would have been obvious to one of 
ordinary skill in the art at the time of the invention to combine Pare/Bianco with Berson, because 
allowing an individual to update and otherwise modify their own personal data while ensuring a 
high-degree of security through the use of biometric authentication helps prevent the fraudulent 
and criminal misuse of personal data. 
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Pare/Bianco/Berson disclose a system wherein personal information may be modified by 
a particular user using physiological identifiers to authenticate the user. Pare/Bianco/Berson do 
not specifically disclose the newly-added limitation of there is established a repository of personal 
information using physiological identifiers to protect against unauthorized modification. 
Kanevsky, however, in at least column 3, lines 10-47; column 5, lines 41-51. It would have been 
obvious to one of ordinary skill in the art at the time of the invention to combine 
Pare/Bianco/Berson with Kanevsky "...a user need enroll (e.g., provide biometric information) 
only once and that information may be subsequently accessed and utilized by multiple biometric 
recognition systems for registration of the user without further enrollment (i.e., the further 
providing of the biometric information) by the user" (see Kanevsky, column 3, lines 3-8). 

Claim 2: 

Pare Jr. et al. shows, in figures 1-16 and related text, medical information is a suitable 
alternative type of data to credit and debit account numbers (column 2, lines 40-48). Therefore it 
would have been obvious to one of skill in the art, at the time of the invention to replace the 
account numbers obtained from the user and stored in the data set (column 13, lines 14-30) with 
the medical information because choosing a suitable alternative from a known list of alternatives 
is common and well known in the art. Pare Jr. et al. fails to explicitly show the user information 
can be modified only if (i) the subject provides a new set of physiological identifiers and (ii) it is 
determined, by recourse to the stored data set, that there is a sufficient match between at least 
one member in the new set and a corresponding member of the first set, so that the subject is 
authenticated as such user. Bianco et al. shows, in figures 1-34 and related text, in an analogous 
art related to the utilization of biometric measurements for the authentication of users, permitting 
a subject to modify information in the stored data set pertinent to such user only if the subject 
provides a new set of physiological identifiers and it is determined, by recourse to the stored data 
set, that there is a sufficient match between at least one member in the new set and a 
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corresponding member of the first set, so that the subject is authenticated as such user (column 
29, lines 5-10). Bianco et al. states that the biometric system (Fig. 1) including the re-enrollment 
step can be usefully incorporated into banking and financial transaction systems (e.g. ATM 
machines) (Bianco, column 58, lines 5-14) therefore, it would have been obvious, at the time of 
the invention, to incorporate the re-enrollment step of Bianco into the biometric ATM access 
system of Pare. 

Claim 3: 

Pare Jr. et al. shows, in figures 1-16 and related text, a method according to claim 1, 
wherein the first set includes a plurality of members (column 13, line 10). 



Claim 4: 

Pare Jr. et al. shows, in figures 1-16 and related text, a method according to claim 1, 
wherein the first set of physiological identifiers includes the appearance of such user's face 
(column 26, lines 42-44). 



Claim 5: 

Pare Jr. et al. shows, in figures 1-16 and related text, a method according to claim 1, 
wherein the first set of physiological identifiers includes characteristics of utterances of such user 
(column 5, lines 22-25). 

Claim 6: 

Pare Jr. et al. shows, in figures 1-16 and related text, a method according to claim 1, 
wherein the first set of physiological identifiers includes a fingerprint of such user (column 5, lines 
22-25). 
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Claim 7: 

Pare Jr. et al. shows, in figures 1-16 and related text, a method according to claim 1, 
wherein the first set of physiological identifiers includes the configuration of an iris in an eye of 
such user (column 5, lines 22-25). 

Claim 8: 

Pare Jr. et al. substantially discloses the invention as claimed but does not explicitly show 
the first set includes at least one member selected from the group consisting of a fingerprint of 
such user and an configuration of an iris in an eye of such user and at least one member selected 
from the group consisting of characteristics of utterances of such user and the appearance of 
such user's face. Bianco et al. shows, in figures 1-34 and related text, in an analogous art related 
to the utilization of biometric measurements for the authentication of users, first set includes at 
least one member selected from the group consisting of a fingerprint of such user and an 
configuration of an iris in an eye of such user and at least one member selected from the group 
consisting of characteristics of utterances of such user and the appearance of such user's face 
(Fig 15). The layering of biometric devices, as shown in Bianco, provides flexibility to apply the 
appropriate level of protection to each resource without decreasing of network productivity 
(column 29, line 60 - column 30, lines 14). 



Claim 9: 

Bianco et al. shows, in figures 1-34 and related text, a method according to claim 1, 
wherein, pursuant to step (d), a subject is permitted to modify information in the sorted data set 
only if the subject provides the new set of physiological identifiers under a condition permitting 
verification, independent of the physiological identifiers, that the new set is being provided by the 
person purporting to provide them (column 28, line 43- column 29, line 39). 
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Claim 10: 

Bianco et al. shows, in figures 1-34 and related text, wherein the condition includes the 
physical presence of the subject when providing the new set (column 29, lines 1-10). 

Claim 11: 

Bianco et al. shows, in figures 1-34 and related text, wherein the condition includes 
having the subject provide the new set when prompted to do so (column 29, lines 1-10). 

Claim 12: 

Bianco et al. shows, in figures 1-34 and related text, wherein the condition includes 
having the subject provide a non-physiological identifier (column 29, lines 1-10). 
Claim 13: 

Bianco et al. shows, in figures 1-34 and related text, wherein the non-physiological 
identifier is selected from the group consisting of a password and a pass card (column 29, lines 1- 
10). 

Claim 14: 

Bianco et al. shows, in figures 1-34 and related text, wherein the non-physiological 
identifier is provided in the course of a session, over a computer network, employing a user's 
public and private keys (column 51, lines 2-4; column 50, lines 35-47). 



Claim 15: 

Bianco et al. shows, in figures 1-34 and related text, prompting each user, on a periodic 
basis, to update the data set pertinent of such user (column 28, lines 43-52). 
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Claims 16 and 39: 

Pare Jr. et al. shows, in figures 1-16 and related text, a method for authenticating a user 
transaction, the method comprising: obtaining a test set of physiological identifiers from a subject 
purporting to be a specific user (column 3, lines 43-46); accessing information in the data set 
pertinent to the specific user stored in accordance with the method of claim 1 (column 3, lines 51- 
55); and determining if there is a sufficient match between at least one member in the test set and 
a corresponding physiological identifier represented in the data set (column 3, lines 51-55). 

In addition, see the rejection and relevant citations in the rejection of claim 1 above. 

Claim 18: 

Pare Jr. et al. shows, in figures 1-16 and related text, the database is accessible via a 
server at a first location (Fig. 1); obtaining the test of physiological identifiers is performed at a 
second location remote from the first location (column 5, lines 1-3, Fig. 3); determining if there is 
a sufficient match includes communicating with the server from the second location over a 
network (column 9, lines 25-27). 



Claim 19: 

Pare Jr. et al. substantially discloses the invention as claimed but fails to show obtaining 
the test set of physiological identifiers is performed under supervision of a merchant. Bianco et 
al. shows, in figures 1-34 and related text, in an analogous art related to the utilization of 
biometric measurements for the authentication of users, obtaining the test set of physiological 
identifiers is performed under supervision of a merchant (column 29, lines 15-21). Employing an 
administrator (merchant) to oversee the enrollment of a user helps ensure that the user enrolling 
is really the right person (column 28, lines 42-53). Therefore, it would have been obvious at the 
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time of the invention to include the administrator of Bianco in the biometric ATM access system of 
Pare. 

Claim 20: 

Bianco et al shows determining if there is a sufficient match is performed without 
revealing content of the first data set to the merchant (column 28, lines 42-53). 

Claims 21-28: 

21-28, Pare Jr. et al. substantially discloses the invention as claimed but fails to show the 
transaction is a change of address for an account, is an application to open an account, the 
account authorizes the transfer of funds, the account is based on the extension of credit to the 
account holder, the transaction is an application to a government agency for one of a license and 
a renewal of a license, the transaction is an application to a government agency for one of a 
license and a renewal of a license. It would have been obvious to one of skill in the art at the time 
of the invention to make the transaction a change of address for an account, an application to 
open an account, an application to a government agency for one of a license and a renewal of a 
license, an application to a government agency for one of a license and a renewal of a license or 
to make the account based on the extension of credit to the account holder because of these 
transactions are well known in the art to require user verification and the invention of Bianco 
describes a method of verifying a user. 

Claim 32: 

Pare Jr. et al. shows, in figures 1-16 and related text, the first set includes a plurality of 
members (column 13, line 10). 



Application/Control Number: Page 12 

09/448,722 

Art Unit: 3621 

Claim 33: 

Pare Jr. et al. substantially discloses the invention as claimed but does not explicitly show 
the first set includes at least one member selected from he group consisting of a fingerprint of the 
user and the configuration of an iris in an eye of the user and at least one member selected from 
the group consisting of characteristics of utterances of he user and the appearance of the user's 
face. Bianco et al. shows, in figures 1-34 and related text, in an analogous art related to the 
utilization of biometric measurements for the authentication of users, first set includes at least one 
member selected from the group consisting of a fingerprint of such user and an configuration of 
an iris in an eye of such user and at least one member selected from the group consisting of 
characteristics of utterances of such user and the appearance of such user's face (Fig 15). The 
layering of biometric devices, as shown in Bianco, provides flexibility to apply the appropriate 
level of protection to each resource without decreasing of network productivity (column 29, line 60 
-column 30, lines 14). 

Claim 34: 

Pare Jr. et al shows, in figures 1-16 and related text, obtaining personal information of 
such user includes obtaining data pertaining to one or more merchants (column 13, lines 13-16). 

Claims 35, 37, and 40: 

Pare Jr. et al shows, in figures 1-16 and related text financial information that may be in 
the data set is not limited to that of a particular banking or financial institution (column 13, lines 
13-16). 
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Claim 38: 

Pare Jr. et al shows, in figures 1-16 and related text discloses, "...DPC site acts as the 
registration site, for implementation simplicity..." (column 13, line 18). 

Claims 41 and 42: 

The combination of Pare/Bianco/Berson/Kanevsky as shown above discloses 
administering registration of a personal information in a data base in a manner tending to assure 
integrity of data and the utilization of biometric measurements for the authentication of users. 
Pare/Bianco do not disclose retaining a representation of at least one of the new set of 
physiological identifiers, if there is an insufficient match, and providing access to the retained 
representation of the at least one of the new set of physiological identifiers by a law enforcement 
official. However, Examiner takes Official Notice that it is old and well known to confiscate 
identifications and other official papers that are being used fraudulently and to then turn them 
over to the proper authorities such as, for example, in the case of a minor trying to purchase 
alcohol or trying to gain entry to and adult establishment, or in the case of an individual using a 
passport or visa belonging to someone else. In each of these cases, the documents are usually 
seized and the suspects are routinely handed over to the proper authorities. 

7. . Claims 43-50 are rejected under 35 U.S.C. 103(a) as being unpatentable over 
Pare/Bianco/Berson/ Kanevsky and further in view of Ginter et al. (US 6,185,683). 

Claims 43 and 45: 

The combination of Pare/Bianco as shown above discloses administering registration of a 
personal information in a database in a manner tending to assure integrity of data and the 
utilization of biometric measurements for the authentication of users. Pare/Bianco do not 
specifically disclose permitting a third party of a specified kind to view but not modify the user's 



Application/Control Number: Page 14 

09/448,722 

Art Unit: 3621 

personal information in the stored data set without requiring such third party to provide a 
physiological identifier that sufficiently matches a corresponding member of the first set of 
physiological identifiers stored in the data set Ginter, however, in column 8, lines 38-45 
discloses, "Secure electronic controls can specify how an item is to be processed or otherwise 
handled (e.g., document cant be modified, can be distributed only to specified persons, 
collections of persons, organizations, can be edited only by certain persons and/or in certain 
manners..." It would have been obvious to combine Pare/Bianco with Ginter because allowing 
third-party persons or organizations to only view but not modify sensitive data provide a benefit of 
controlling the rights management and secure chain of handling and control, preventing 
fraudulent use of personal data. r * 



Claim 44: 

Pare Jr. et al shows, in figures 1-16 and related text, obtaining personal information of 
such user includes obtaining data pertaining to one or more merchants (column 13, lines 13-16). 

Claim 46: 

The combination of Pare/Bianco/Ginter as shown above discloses administering 
registration of a personal information in a database in a manner tending to assure integrity of data 
and the utilization of biometric measurements for the authentication of users. Pare/Bianco/Ginter 
do not specifically disclose that the specified kind is a health care provider. However, Bianco, in 
column 20, lines 16-32 discloses access to medical records and patient information, inherently 
disclosing that a health care provider needs access to such information. It would have been 
obvious to combine Pare/Bianco/Ginter because allowing third-party persons or organizations 
such as health care providers access to patient data provides a benefit of controlling the rights 
management and secure chain of handling and control, while providing health care services. 



Application/Control Number: Page 15 

09/448,722 

Art Unit: 3621 

Claims 47-50: 

The combination of Pare/Bianco as shown above discloses administering registration of a 
personal information in a database in a manner tending to assure integrity of data and the 
utilization of biometric measurements for the authentication of users. Pare/Bianco do not 
specifically disclose the following, but Ginter does a shown: 

• providing, to each user, a token indicating that the user has provided information 
to the data base (column 8, lines 15-22); 

• the token comprises a card (column 8, lines 63-65); 

• the token includes an identifier that, when presented to the data base by a third 
party, enables such third party to access but not modify the user's information in 
the data base (column 8, lines 63-65); 

• the identifier comprises a record number identifying the data set pertinent to such 
user (column 41 , lines 37-40). 

As shown above, Ginter, in column 8, lines 38-45 discloses, "Secure electronic controls 
can specify how an item is to be processed or otherwise handled (e.g., document can't be 
modified, can be distributed only to specified persons, collections of persons, organizations, can 
be edited only by certain persons and/or in certain manners..." It would have been obvious to 
combine Pare/Bianco with Ginter because allowing third-party persons or organizations to only 
view but not modify sensitive data provide a benefit of controlling the rights management and 
secure chain of handling and control, preventing fraudulent use of personal data. 
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Any inquiry concerning this communication or earlier communications from the examiner 
should be directed to James A. Reagan whose telephone number is (703) 306*9131. The 
examiner can normally be reached on Monday-Friday, 9:30am-5:00pm. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, James Trammell can be reached at (703) 305-9768. 

Any inquiry of a general nature or relating to the status of this application or proceeding 
should be directed to the Receptionist whose telephone number is (703) 305-3900. Information 
regarding the status of an application may be obtained from the Patent Application Information 
Retrieval (PAIR) system. Status information for published applications may be obtained from 
either Private PAIR or Public PAIR. Status information for unpublished applications is available 
through Private PAIR only. For more information about the PAIR system, see 
http://portal.uspto.Qov/external/Dortal/pair . Should you have questions on access to the Private 
PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). 

Any response to this action should be mailed to: 



(703) 305-7687 [Official communications; including 
After Final communications labeled "Box AF n ] 

(703) 308-1396 [Informal/Draft communications, labeled "PROPOSED" 
or "DRAFT"] 

Hand delivered responses should be brought to Crystal Park 5, 2451 Crystal Drive, 
Arlington, VA, 7 th floor receptionist. 
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